Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been addressed in the Linux kernel's Direct Rendering Manager (DRM) XE migration process. This issue arose because, in certain error scenarios, a previous synchronization fence could be released before it was properly waited on, leading to potential memory management errors. The vulnerability has been fixed by adjusting the order of operations to ensure that fences are only released after they have been waited on.
Exploitation of this vulnerability could lead to a use-after-free condition, which may be exploited to execute arbitrary code or cause a denial-of-service by crashing the system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.